Privacy Policy for www.phishing-simulatie.nl

The privacy statement for the website www.phishing-simulatie.nl is identical to the privacy policy of BSM Business Security Management B.V. This website about phishing simulation tests is part of the services provided by BSM Business Security Management B.V., hereinafter referred to as BSM.

Since May 25, all EU countries protect your privacy according to the same regulations. In our Privacy Statement, we explain what personal data we collect and how we process it. BSM does not process personal data on a large scale and will never resell this data. Your information is safe and secure with us.

 

General Information

BSM Business Security Management B.V. (BSM), established in Amsterdam, is responsible for the processing of personal data as described in this privacy statement.

Contact details: BSM, Keizersgracht 241, 1016 EA Amsterdam, +31 (0)20 8203693

https://www.bsm.nl, info@bsm.nl

Personal Data We Process

BSM may process your personal data because you use our services and/or because you provide this information to us. It is also possible that we have obtained your personal data as part of an investigation.

Data we process includes:

  • First and last name
  • Address information
  • Date of birth
  • Place of birth
  • Professional activities
  • Phone number
  • Email address
  • Opt-in data for our newsletters and advertising
  • Special personal data in investigation case files
  • Action/tracking numbers and IP addresses of customers

Special and/or Sensitive Personal Data We Process

Our website and services do not intend to collect data about website visitors who are younger than 16 years old, unless they have permission from parents or guardians. However, we cannot verify whether a visitor is older than 16. We therefore advise parents to be involved in their children’s online activities, to prevent data being collected about children without parental consent. If you believe that we have collected personal information about a minor without consent, please contact us at info@bsm.nl.

Purpose of Processing

BSM Business Security Management B.V. processes your personal data for the following purposes:

  • to contact you
  • to process our financial agreement
  • to be able to call or email you if necessary to perform our services
  • advising on information security, fraud prevention, and identity
  • security-related matters
  • advising on cybersecurity
  • BSM also processes personal data when we are legally obligated to do so, such as data we need for our tax return
  • to arrange your modification of a service by BSM
  • sending our newsletter and/or promotional brochure
  • to deliver goods and services to you
  • to manage your products (managed firewalls)
  • for requesting services with our check-tools (options for customers to test their own security) on the BSM website

During most of our audit and penetration testing activities, the analyzed data consists of technical information such as server settings and documents regarding procedures. Especially when recording security flaws where non-anonymized access has been obtained to personal data, these are only recorded in screenshots in an anonymized form.

BSM is the data controller. For the processing of data related to our phishing simulations and security awareness training, we follow the guidelines of the General Data Protection Regulation (GDPR). When we conduct investigation cases in exceptional circumstances, we also adhere to the Dutch Private Security Organizations and Investigation Agencies Act (Wpbr) and the associated privacy code of conduct.


Automated Decision-making

BSM Business Security Management B.V. does not make decisions based on automated processing on matters that can have significant consequences for individuals. These are decisions that are made by computer programs or systems, without human intervention (for example, an employee of BSM Business Security Management B.V.).

How Long We Store Personal Data / Retention Period

BSM does not store your personal data longer than strictly necessary to achieve the purposes for which your data is collected and as long as the law requires us to retain your data. The exact duration varies. For example, the retention period for invoice data ends after their mandatory 7-year retention period for tax authorities, or, for example, upon termination of an agreement between the client and BSM, customer data is cleared with the exception of data that legally requires a longer retention period.

We retain OPT-IN data until cancellation by the customer.

Cancellation can be done by sending an email with (in the title) the request to unsubscribe from newsletters and/or advertising, preferably as follows:

Request to unsubscribe email, do not unsubscribe for regular mail/post Request to unsubscribe regular mail/post, do not unsubscribe for email Request to unsubscribe email and regular mail/post.

Sharing Personal Data with Third Parties

BSM Business Security Management B.V. does not sell your data to third parties and only provides it if necessary for the execution of our agreement with you or to comply with a legal obligation. With companies that process your data on our behalf, we enter into a processor agreement to ensure the same level of security and confidentiality of your data. BSM Business Security Management B.V. remains responsible for these processing operations. Sharing of data is limited to our payment provider(s) and companies we hire for the execution of advisory or other assignments. For the processing of data related to our phishing simulations and security awareness training, we follow the guidelines of the General Data Protection Regulation (GDPR). When we conduct investigation cases in exceptional circumstances, we also adhere to the Dutch Private Security Organizations and Investigation Agencies Act (Wpbr) and the associated privacy code of conduct.

Cookies, or Similar Techniques, That We Use

BSM Business Security Management B.V. only uses technical and functional cookies, and analytical cookies that do not infringe on your privacy. A cookie is a small text file that is stored on your computer, tablet, or smartphone when you first visit this website. The cookies we use are necessary for the technical operation of the website and your ease of use. They ensure that the website works properly and remember, for example, your preferences. We can also optimize our website with them. You can opt out of cookies by setting your internet browser so that it no longer stores cookies. In addition, you can also delete all information previously stored via your browser settings. Besides technical cookies, we use Google Analytics so that we can measure and manage our marketing activities. The data from Google does not contain information such as name and address; it mainly concerns the number of visitors to the BSM website on a given day and from what type of device this is done. The purpose of this is to optimize our website for our visitors and to measure the effectiveness of marketing campaigns.

View, Modify, or Delete Data

You have the right to view, correct, or delete your personal data. Additionally, you have the right to withdraw your consent to data processing or to object to the processing of your personal data by BSM Business Security Management B.V., and you have the right to data portability. This means that you can submit a request to us to send the personal data we have about you in a computer file to you or another organization specified by you. You can send a request for access, correction, deletion, data transfer of your personal data, or request for withdrawal of your consent or objection to the processing of your personal data to info@bsm.nl. To ensure that the request for access has been made by you, we ask you to send a copy of your ID with the request. In this copy, black out your passport photo, MRZ (machine readable zone, the strip with numbers at the bottom of the passport), passport number, and Citizen Service Number (BSN). This is to protect your privacy. We will respond to your request as soon as possible, but within four weeks. BSM Business Security Management B.V. would also like to point out that you have the option to file a complaint with the national supervisory authority, the Dutch Data Protection Authority. This can be done via the following link: https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-ons

How We Secure Personal Data

BSM Business Security Management B.V. takes the protection of your data seriously and takes appropriate measures to prevent misuse, loss, unauthorized access, unwanted disclosure, and unauthorized modification. We do this, among other things, by placing a security certificate on our website. If you have the impression that your data is not properly secured or there are indications of abuse, please contact our customer service or via info@bsm.nl.